Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Procedure Networking Cache Disk Security' = 'C:\udxqfjnvqlgw\ahuznkzcz.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Access Routing Player Ordering Portable] 'ImagePath' = 'C:\udxqfjnvqlgw\ahuznkzcz.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Access Routing Player Ordering Portable] 'Start' = '00000002'
- 'C:\udxqfjnvqlgw\slmyomn.exe' "c:\udxqfjnvqlgw\ahuznkzcz.exe"
- 'C:\udxqfjnvqlgw\ahuznkzcz.exe'
- 'C:\udxqfjnvqlgw\sh4g2s1zlueus1kf.exe'
- C:\udxqfjnvqlgw\ahuznkzcz.exe
- C:\udxqfjnvqlgw\slmyomn.exe
- C:\udxqfjnvqlgw\ifkr5yvgp
- %WINDIR%\udxqfjnvqlgw\ujwxpc
- C:\udxqfjnvqlgw\ujwxpc
- C:\udxqfjnvqlgw\sh4g2s1zlueus1kf.exe
- C:\udxqfjnvqlgw\slmyomn.exe
- C:\udxqfjnvqlgw\ahuznkzcz.exe
- C:\udxqfjnvqlgw\sh4g2s1zlueus1kf.exe
- %WINDIR%\udxqfjnvqlgw\ujwxpc
- 'fe###wevery.net':80
- 'do###eevery.net':80
- 'fe####charge.net':80
- 'fe#####ifference.net':80
- 'br####single.net':80
- 're####charge.net':80
- 'br#####ifference.net':80
- 're####single.net':80
- 'br####charge.net':80
- 'do####charge.net':80
- 'pr####charge.net':80
- 'do####single.net':80
- 'pr####single.net':80
- 'do#####ifference.net':80
- 'pr###yevery.net':80
- 'fe####single.net':80
- 'pr#####ifference.net':80
- 'do###revery.net':80
- 're#####ifference.net':80
- 'st####thcharge.net':80
- 'st#####hdifference.net':80
- 'de###eevery.net':80
- 'st####thsingle.net':80
- 'st####thevery.net':80
- 'ex###tspent.net':80
- 'be####espent.net':80
- 'ex####matter.net':80
- 'be####ematter.net':80
- 'pr####esingle.net':80
- 'de####single.net':80
- 'br###nevery.net':80
- 're###tevery.net':80
- 'pr####echarge.net':80
- 'de#####ifference.net':80
- 'pr####eevery.net':80
- 'de####charge.net':80
- 'pr#####difference.net':80
- 'mi###every.net':80
- 'st###period.net':80
- 'st####thhowever.net':80
- 'st####lthough.net':80
- 'st####thperiod.net':80
- 'st####owever.net':80
- 'mo####ntcharge.net':80
- 'ou####echarge.net':80
- 'mo####ntsingle.net':80
- 'ou####esingle.net':80
- 'pr####eperiod.net':80
- 'de####period.net':80
- 'pr####ealthough.net':80
- 'de####although.net':80
- 'pr####ehowever.net':80
- 'st###choose.net':80
- 'st#####halthough.net':80
- 'de####however.net':80
- 'st####thchoose.net':80
- 'mo#####tdifference.net':80
- 'st###single.net':80
- 'mi###single.net':80
- 'bu####ngevery.net':80
- 'ev####gevery.net':80
- 'st###charge.net':80
- 'mi####ifference.net':80
- 'st###every.net':80
- 'mi###charge.net':80
- 'st####ifference.net':80
- 'ou####eevery.net':80
- 'bu####ngsingle.net':80
- 'ou#####difference.net':80
- 'mo####ntevery.net':80
- 'ev####gsingle.net':80
- 'bu#####gdifference.net':80
- 'ev#####difference.net':80
- 'bu####ngcharge.net':80
- 'ev####gcharge.net':80
- http://fe###wevery.net/index.php?me########
- http://do###eevery.net/index.php?me########
- http://fe####charge.net/index.php?me########
- http://fe#####ifference.net/index.php?me########
- http://br####single.net/index.php?me########
- http://re####charge.net/index.php?me########
- http://br#####ifference.net/index.php?me########
- http://re####single.net/index.php?me########
- http://br####charge.net/index.php?me########
- http://do####charge.net/index.php?me########
- http://pr####charge.net/index.php?me########
- http://do####single.net/index.php?me########
- http://pr####single.net/index.php?me########
- http://do#####ifference.net/index.php?me########
- http://pr###yevery.net/index.php?me########
- http://fe####single.net/index.php?me########
- http://pr#####ifference.net/index.php?me########
- http://do###revery.net/index.php?me########
- http://re#####ifference.net/index.php?me########
- http://st####thcharge.net/index.php?me########
- http://st#####hdifference.net/index.php?me########
- http://de###eevery.net/index.php?me########
- http://st####thsingle.net/index.php?me########
- http://st####thevery.net/index.php?me########
- http://ex###tspent.net/index.php?me########
- http://be####espent.net/index.php?me########
- http://ex####matter.net/index.php?me########
- http://be####ematter.net/index.php?me########
- http://pr####esingle.net/index.php?me########
- http://de####single.net/index.php?me########
- http://br###nevery.net/index.php?me########
- http://re###tevery.net/index.php?me########
- http://pr####echarge.net/index.php?me########
- http://de#####ifference.net/index.php?me########
- http://pr####eevery.net/index.php?me########
- http://de####charge.net/index.php?me########
- http://pr#####difference.net/index.php?me########
- http://mi###every.net/index.php?me########
- http://st###period.net/index.php?me########
- http://st####thhowever.net/index.php?me########
- http://st####lthough.net/index.php?me########
- http://st####thperiod.net/index.php?me########
- http://st####owever.net/index.php?me########
- http://mo####ntcharge.net/index.php?me########
- http://ou####echarge.net/index.php?me########
- http://mo####ntsingle.net/index.php?me########
- http://ou####esingle.net/index.php?me########
- http://pr####eperiod.net/index.php?me########
- http://de####period.net/index.php?me########
- http://pr####ealthough.net/index.php?me########
- http://de####although.net/index.php?me########
- http://pr####ehowever.net/index.php?me########
- http://st###choose.net/index.php?me########
- http://st#####halthough.net/index.php?me########
- http://de####however.net/index.php?me########
- http://st####thchoose.net/index.php?me########
- http://mo#####tdifference.net/index.php?me########
- http://st###single.net/index.php?me########
- http://mi###single.net/index.php?me########
- http://bu####ngevery.net/index.php?me########
- http://ev####gevery.net/index.php?me########
- http://st###charge.net/index.php?me########
- http://mi####ifference.net/index.php?me########
- http://st###every.net/index.php?me########
- http://mi###charge.net/index.php?me########
- http://st####ifference.net/index.php?me########
- http://ou####eevery.net/index.php?me########
- http://bu####ngsingle.net/index.php?me########
- http://ou#####difference.net/index.php?me########
- http://mo####ntevery.net/index.php?me########
- http://ev####gsingle.net/index.php?me########
- http://bu#####gdifference.net/index.php?me########
- http://ev#####difference.net/index.php?me########
- http://bu####ngcharge.net/index.php?me########
- http://ev####gcharge.net/index.php?me########
- DNS ASK fe###wevery.net
- DNS ASK do###eevery.net
- DNS ASK fe####charge.net
- DNS ASK fe#####ifference.net
- DNS ASK br####single.net
- DNS ASK re####charge.net
- DNS ASK br#####ifference.net
- DNS ASK re####single.net
- DNS ASK br####charge.net
- DNS ASK do####charge.net
- DNS ASK pr####charge.net
- DNS ASK do####single.net
- DNS ASK pr####single.net
- DNS ASK do#####ifference.net
- DNS ASK pr###yevery.net
- DNS ASK fe####single.net
- DNS ASK pr#####ifference.net
- DNS ASK do###revery.net
- DNS ASK re#####ifference.net
- DNS ASK st####thcharge.net
- DNS ASK st#####hdifference.net
- DNS ASK de###eevery.net
- DNS ASK st####thsingle.net
- DNS ASK st####thevery.net
- DNS ASK ex###tspent.net
- DNS ASK be####espent.net
- DNS ASK ex####matter.net
- DNS ASK be####ematter.net
- DNS ASK pr####esingle.net
- DNS ASK de####single.net
- DNS ASK br###nevery.net
- DNS ASK re###tevery.net
- DNS ASK pr####echarge.net
- DNS ASK de#####ifference.net
- DNS ASK pr####eevery.net
- DNS ASK de####charge.net
- DNS ASK pr#####difference.net
- DNS ASK mi###every.net
- DNS ASK st###period.net
- DNS ASK st####thhowever.net
- DNS ASK st####lthough.net
- DNS ASK st####thperiod.net
- DNS ASK st####owever.net
- DNS ASK mo####ntcharge.net
- DNS ASK ou####echarge.net
- DNS ASK mo####ntsingle.net
- DNS ASK ou####esingle.net
- DNS ASK pr####eperiod.net
- DNS ASK de####period.net
- DNS ASK pr####ealthough.net
- DNS ASK de####although.net
- DNS ASK pr####ehowever.net
- DNS ASK st###choose.net
- DNS ASK st#####halthough.net
- DNS ASK de####however.net
- DNS ASK st####thchoose.net
- DNS ASK mo#####tdifference.net
- DNS ASK st###single.net
- DNS ASK mi###single.net
- DNS ASK bu####ngevery.net
- DNS ASK ev####gevery.net
- DNS ASK st###charge.net
- DNS ASK mi####ifference.net
- DNS ASK st###every.net
- DNS ASK mi###charge.net
- DNS ASK st####ifference.net
- DNS ASK ou####eevery.net
- DNS ASK bu####ngsingle.net
- DNS ASK ou#####difference.net
- DNS ASK mo####ntevery.net
- DNS ASK ev####gsingle.net
- DNS ASK bu#####gdifference.net
- DNS ASK ev#####difference.net
- DNS ASK bu####ngcharge.net
- DNS ASK ev####gcharge.net
- ClassName: 'Shell_TrayWnd' WindowName: ''